← back
CVE-2023-46214highCWE-91

Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing

58Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 8epss 89%
from disclosure to weapon12 days
Published on NVDNov 16
metasploit+12d
exploitation probability
89%top 1% of all CVEs
observed exploitation
nono source reports it
In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H